Record summary

CVE-2026-0637 has a selected CVSS score of 4.4 (medium).

Description

When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access to the 'wso2carbon' log files could retrieve sensitive information, such as user credentials or other confidential data, that was inadvertently logged due to misconfiguration, potentially leading to unauthorized access.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2026 · Source: CVE List

Affected products and versions

9
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListBefore 4.5.0unknown
4.5.0 to < 4.5.0.50affected
4.6.0 to < 4.6.0.14affected

Default status: unaffected

CVE ListBefore 3.1.0unknown
3.1.0 to < 3.1.0.357affected
3.2.0 to < 3.2.0.465affected
3.2.1 to < 3.2.1.84affected
4.1.0 to < 4.1.0.249affected
4.2.0 to < 4.2.0.189affected
4.3.0 to < 4.3.0.100affected
4.4.0 to < 4.4.0.64affected
4.5.0 to < 4.5.0.49affected
4.6.0 to < 4.6.0.13affected

WSO2 Carbon Event Publisher Core

Browse WSO2 / WSO2 Carbon Event Publisher Coreorg.wso2.carbon.analytics-common:org.wso2.carbon.event.publisher.core

Default status: unknown

CVE List5.2.24 to < 5.2.24.11affected
5.2.26 to < 5.2.26.24affected
5.2.27 to < 5.2.27.7affected
5.2.41 to < 5.2.41.8affected
5.2.45 to < 5.2.45.2affected
5.2.50 to < 5.2.50.3affected
5.2.57 to < 5.2.57.12affected
5.2.58 to < 5.2.58.3affected
5.2.61 to < 5.2.61.4affected
5.2.64 to < 5.2.64.1affected
5.3.5 to < 5.3.5.10affected
5.3.11 to < 5.3.11.7affected
Showing 12 of 16 version ranges

Default status: unaffected

CVE ListBefore 5.10.0unknown
5.10.0 to < 5.10.0.386affected
5.11.0 to < 5.11.0.433affected
6.0.0 to < 6.0.0.260affected
6.1.0 to < 6.1.0.261affected
7.0.0 to < 7.0.0.139affected
7.1.0 to < 7.1.0.47affected
7.2.0 to < 7.2.0.8affected

WSO2 Identity Server as Key Manager

Browse WSO2 / WSO2 Identity Server as Key Manager

Default status: unaffected

CVE ListBefore 5.10.0unknown
5.10.0 to < 5.10.0.377affected

Default status: unaffected

CVE ListBefore 2.0.0unknown
2.0.0 to < 2.0.0.406affected

Default status: unaffected

CVE ListBefore 2.0.0unknown
2.0.0 to < 2.0.0.426affected

Default status: unaffected

CVE ListBefore 4.5.0unknown
4.5.0 to < 4.5.0.48affected
4.6.0 to < 4.6.0.13affected

Default status: unaffected

CVE ListBefore 4.5.0unknown
4.5.0 to < 4.5.0.49affected
4.6.0 to < 4.6.0.13affected

References

2